- Sources: bulletin
- Summary: Qubes states that Intel's five advisories do not carry enough information for a definitive assessment and that it cannot exclude a cross-qube attack, meaning one compromised qube inferring data from another or escalating privileges. Affected parts are 10th and 11th generation Intel Core, Core Ultra Series 1 to 3, and various Xeon. Intel has withdrawn the update for Meteor Lake, Core Ultra Series 2, citing functional issues, while the Qubes 4.3 fix for the rest is microcode_ctl 2.1.20260812, already in stable.
- Why it matters: Meteor Lake systems have no fix and an exposure Qubes says it cannot bound, and applying the fix elsewhere needs a dom0 restart plus an Anti Evil Maid reseal because PCR18 and PCR19 change.
- Follow-up: Intel has not republished the Meteor Lake microcode, so Core Ultra Series 2 exposure needs re-checking.
send feedback on this story